Home / May 02, 2026 / Story
0
#9 The Hacker News general May 01, 2026 at 09:43 UTC

Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft

By [email protected] (The Hacker News)

AI Summary

The GitHub account 'BufferZoneCorp' published malicious Ruby gems and Go modules targeting CI pipelines for credential theft, GitHub Actions tampering, and SSH persistence. The supply chain attack uses sleeper packages to subsequently deliver malicious payloads in development environments.

Relevance score: 72.0/100

# More from May 02